Improper Access Control in Intel FPGA SDK for OpenCL with Quartus Prime Pro Edition
CVE-2022-34157

6.7MEDIUM

Key Information:

Summary

The Intel FPGA SDK for OpenCL, specifically with the Quartus Prime Pro Edition software prior to version 22.1, contains a vulnerability related to improper access control. This flaw enables authenticated users to potentially escalate their privileges through local access. Malicious actors could exploit this weakness to gain unauthorized control over sensitive system resources, posing a significant risk to operational integrity.

Affected Version(s)

Intel(R) FPGA SDK for OpenCL(TM) with Intel(R) Quartus(R) Prime Pro Edition software before version 22.1

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.